Logo image
Efficient three-party authentication and key agreement protocols resistant to password guessing attacks
Journal article   Peer reviewed

Efficient three-party authentication and key agreement protocols resistant to password guessing attacks

Her-Tyan Yeh, Hung-Min Sun and Tzonelih Hwang
Journal of Information Science and Engineering, Vol.19(6), pp.1059-1070
11/2003

Abstract

Authentication Key agreement Network protocol Password guessing attack Perfect forward secrecy
Three-party EKE was proposed to establish a session key between two clients through a server. However, three-party EKE is insecure against undetectable on-line and off-line password guessing attacks. In this paper, we first propose an enhanced three-party EKE to withstand the security risk in three-party EKE. We also propose a verifier-based three-party EKE that is more secure than a plaintext-equivalent mechanism in which a compromise of the server's database will not result in success in directly impersonating clients.

Metrics

1 Record Views

Details

Logo image